VLDB 2026 Research / reviewers in the wild / expert
Christian T. Zenger
dblp:130/6535
· DBLP profile ↗
14ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0003-1638-948XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 5 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper DetectionabstractMany computing systems need to be protected against physical attacks using active tamper detection based on sensors. One technical solution is to employ an Anti-Tamper Radio (ATR) approach, analyzing the radio wave propagation effects within a protected device to detect unauthorized physical alterations. However, ATR systems face key challenges in terms of susceptibility to signal manipulation attacks, limited reliability due to environmental noise, and regulatory constraints from wide bandwidth usage. Maryam Shaygan Tabar, Johannes Kortz, Paul Staat, Harald Elders-Boll, Christof Paar, Christian T. Zenger |
WISEC | 6 |
| 2024 | RIS-Jamming: Breaking Key Consistency in Channel Reciprocity-Based Key GenerationabstractChannel Reciprocity-based Key Generation (CRKG) exploits reciprocal channel randomness to establish shared secret keys between wireless terminals. This new security technique is expected to complement existing cryptographic techniques for secret key distribution of future wireless networks. In this paper, we present a new attack, reconfigurable intelligent surface (RIS) jamming, and show that an attacker can prevent legitimate users from agreeing on the same key by deploying a malicious RIS to break channel reciprocity. Specifically, we elaborate on three examples to implement the RIS-jamming attack: Using active nonreciprocal circuits, performing time-varying controls, and reducing the signal-to-noise ratio. The attack effect is then studied by formulating the secret key rate with a relationship to the deployment of RIS. To resist such RIS-jamming attacks, we propose a countermeasure that exploits wideband signals for multipath separation. The malicious RIS path is distinguished from all separated channel paths, and thus the countermeasure is referred to as contaminated path removal-based CRKG (CPR-CRKG). We present simulation results, showing that legitimate users under RIS jamming are still able to generate secret keys from the remaining paths. We also experimentally demonstrate the RIS-jamming attack by using commodity Wi-Fi devices in conjunction with a fabricated RIS prototype. In our experiments, we were able to increase the average bit disagreement ratio (BDR) of raw secret keys by 20%. Further, we successfully demonstrate the proposed CPR-CRKG countermeasure to tackle RIS jamming in wideband systems as long as the source of randomness and the RIS propagation paths are separable. Guyue Li, Paul Staat, Markus Heinrichs, Christian T. Zenger, Rainer Kronberger, Harald Elders-Boll, Christof Paar, Aiqun Hu |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Mirror, Mirror on the Wall: Wireless Environment Reconfiguration Attacks Based on Fast Software-Controlled SurfacesabstractThe intelligent reflecting surface (IRS) is a promising new paradigm in wireless communications for meeting the growing connectivity demands in next-generation mobile networks. IRS, also known as software-controlled metasurfaces, consist of an array of adjustable radio wave reflectors, enabling smart radio environments, e.g., for enhancing the signal-to-noise ratio (SNR) and spatial diversity of wireless channels. Research on IRS to date has been largely focused on constructive applications. Paul Staat, Harald Elders-Boll, Markus Heinrichs, Christian T. Zenger, Christof Paar |
AsiaCCS | 4 |
| 2022 | Anti-Tamper Radio: System-Level Tamper Detection for Computing SystemsabstractA whole range of attacks becomes possible when adversaries gain physical access to computing systems that process or contain sensitive data. Examples include side-channel analysis, bus probing, device cloning, or implanting hardware Trojans. Defending against these kinds of attacks is considered a challenging endeavor, requiring anti-tamper solutions to monitor the physical environment of the system. Current solutions range from simple switches, which detect if a case is opened, to meshes of conducting material that provide more fine-grained detection of integrity violations. However, these solutions suffer from an intricate trade-off between physical security on the one side and reliability, cost, and difficulty to manufacture on the other.In this work, we demonstrate that radio wave propagation in an enclosed system of complex geometry is sensitive against adversarial physical manipulation. We present an anti-tamper radio (ATR) solution as a method for tamper detection, which combines high detection sensitivity and reliability with ease-of-use. ATR constantly monitors the wireless signal propagation behavior within the boundaries of a metal case. Tamper attempts such as insertion of foreign objects, will alter the observed radio signal response, subsequently raising an alarm.The ATR principle is applicable in many computing systems that require physical security such as servers, ATMs, and smart meters. As a case study, we use 19” servers and thoroughly investigate capabilities and limits of the ATR. Using a custom-built automated probing station, we simulate probing attacks by inserting needles with high precision into protected environments. Our experimental results show that our ATR implementation can detect 16mm insertions of needles of diameter as low as 0.1mm under ideal conditions. In the more realistic environment of a running 19” server, we demonstrate reliable detection of 40mm insertions of needles of diameter 1mm for a period of 10 days. Paul Staat, Johannes Tobisch, Christian T. Zenger, Christof Paar |
SP | 3 |
| 2022 | Analog Physical-Layer Relay Attacks with Application to Bluetooth and Phase-Based RangingabstractToday, we use smartphones as multi-purpose devices that communicate with their environment to implement context-aware services, including asset tracking, indoor localization, contact tracing, or access control. As a de-facto standard, Bluetooth is available in virtually every smartphone to provide short-range wireless communication. Importantly, many Bluetooth-driven applications such as Phone as a Key (PaaK) for vehicles and buildings require proximity of legitimate devices, which must be protected against unauthorized access. In earlier access control systems, attackers were able to violate proximity-verification through relay station attacks. However, the vulnerability of Bluetooth against such attacks was yet unclear as existing relay attack strategies are not applicable or can be defeated through wireless distance measurement. Paul Staat, Kai Jansen, Christian T. Zenger, Harald Elders-Boll, Christof Paar |
WISEC | 3 |
| 2021 | Kalman Filter Based MIMO CSI Phase Recovery for COTS Wifi DevicesabstractRecently channel state information (CSI) measurements from commercial multi-input multi-output (MIMO) WiFi systems have been ubiquitously used for different wireless sensing applications. However, the phase of the CSI realizations is usually distorted severely by phase errors due to the hardware impairments, which significantly reduce the sensing performance. In this paper, we directly utilize the modeling of the phase distortions caused by the hardware impairments and propose an adaptive CSI estimation approach based on Kalman filter (KF) with maximum-a-posteriori (MAP) estimation that considers the CSI from the previous time. The performance of the proposed algorithm is compared against the Cramér–Rao lower bound (CRLB). Simulation and experimental results demonstrate that our approach can track the channel variations while eliminating the phase errors accurately. Jeremy Brauer, Aydin Sezgin, Christian T. Zenger |
ICASSP | 4 |
| 2021 | Keys from the Sky: A First Exploration of Physical-Layer Security Using Satellite LinksabstractIn this paper, we investigate physical-layer security (PLS) methods for proximity-based group-key establishment and proof of location. Fields of application include secure car-to-car communication, privacy-preserving and secure distance evidence for healthcare, or location-based feature activation. Existing technologies do not solve the problem satisfactorily due to communication restrictions, e.g., ultra-wideband (UWB) based time of flight measurements, or trusted hardware, e.g., using global navigation satellite system (GNSS) positioning data.We introduce PLS as a possible solution candidate. It is information-theoretically secure, thereby also post-quantum resistant, and has the potential to run on resource-constrained devices with low latency. We use wireless channel properties of satellite-to-earth links, demonstrate the first feasibility study using off-the-shelf hardware testbeds, and present first evaluation results and future directions for research. Pascal Zimmer, Roland Weinreich, Christian T. Zenger, Aydin Sezgin, Christof Paar |
ICC | 3 |
| 2021 | Intelligent Reflecting Surface-Assisted Wireless Key Generation for Low-Entropy EnvironmentsabstractPhysical layer key generation is a promising candidate for cryptographic key establishment between two wireless communication parties. It offers information-theoretic security and is an attractive alternative to public-key techniques. Here, the inherent randomness of wireless radio channels is used as a shared entropy source to generate cryptographic key material. However, practical implementations often suffer from static channel conditions which exhibit a limited amount of randomness. In the past, considerable research efforts have been made to address this fundamental limitation. However, current solutions are not generic or require dedicated hardware extensions such as reconfigurable antennas. In this paper, we propose a novel wireless key generation architecture based on randomized channel responses from an intelligent reflecting surface (IRS). Due to its passive nature, a cooperative IRS is well-suited to provide randomness for conventional resource-constrained radios. We conduct the first practical studies to successfully demonstrate IRS-based physical-layer key generation with an OFDM system. In a static environment, using a single subcarrier only, our IRS-assisted prototype system achieves a key generation rate (KGR) of 97.39 bps with 6.5% key disagreement rate (KDR) after quantization, while passing standard randomness tests. Paul Staat, Harald Elders-Boll, Markus Heinrichs, Rainer Kronberger, Christian T. Zenger, Christof Paar |
PIMRC | 5 |
| 2016 | Constructive and Destructive Aspects of Adaptive Wormholes for the 5G Tactile InternetabstractIn this work, we constructively combine adaptive wormholes with channel-reciprocity based key establishment (CRKE), which has been proposed as a lightweight security solution for IoT devices and might be even more important for the 5G Tactile Internet and its embedded low-end devices. We present a new secret key generation protocol where two parties compute shared cryptographic keys under narrow-band multi-path fading models over a delayed digital channel. The proposed approach furthermore enables distance-bounding the key establishment process via the coherence time dependencies of the wireless channel. Our scheme is thoroughly evaluated both theoretically and practically. For the latter, we used a testbed based on the IEEE 802.15.4 standard and performed extensive experiments in a real-world manufacturing environment. Additionally, we demonstrate adaptive wormhole attacks (AWOAs) and their consequences on several physical-layer security schemes. Furthermore, we proposed a countermeasure that minimizes the risk of AWOAs. Christian T. Zenger, Jan Zimmer, Mario Pietersz, Benedikt Driessen, Christof Paar |
WISEC | 1 |
| 2016 | Authenticated key establishment for low-resource devices exploiting correlated random channels
Christian T. Zenger, Mario Pietersz, Jan Zimmer, Jan-Felix Posielek, Thorben Lenze, Christof Paar |
Comput. Networks | 1 |
| 2015 | On-line Entropy Estimation for Secure Information ReconciliationabstractThe random number generator (RNG) is a critical, if not in fact the most important, component in every cryptographic device. Introducing the symmetric radio channel, represented by estimations of location-specific, reciprocal, and time- variant channel characteristics, as a common RNG is not a trivi Christian T. Zenger, Jan Zimmer, Jan-Felix Posielek, Christof Paar |
MobiQuitous | 1 |
| 2015 | Exploiting the Physical Environment for Securing the Internet of ThingsabstractUsing the randomness provided by the physical environment to build security solutions has received much attention recently. In particular, the shared entropy provided by measuring ambient audio, luminosity modalities or electromagnetic emanations has been used to build location-based, proximity-based, or context-based security mechanisms. The majority of those protocols is based on a standard model consisting channel probing, quantization, information reconciliation, privacy amplification, and key verification. The main problem for almost all approaches is the limited understanding of the security that is provided. For example, security analyses often only address single components and not the entire system or are based on broad abstractions of the physical source of randomness. Further, a big open question is the feasibility of such systems for low-resource platforms. Our first contribution is a detailed, optimized realization of a key establishment system. We demonstrate the feasibility of deriving a shared secret from correlated quantities on resource-constrained devices with tight power budget. Our system was realized on the popular ARM Cortex-M3 processor that reports detailed resource requirements. The second major contribution is a summary and abstraction of previous works together with a rigorous security analysis. We substantiate our investigation by presenting practical attack results. Christian T. Zenger, Jan Zimmer, Mario Pietersz, Jan-Felix Posielek, Christof Paar |
NSPW | 1 |
| 2015 | Bringing PHY-Based Key Generation into the Field: An Evaluation for Practical ScenariosabstractThe need for secured communication between computationally weak wireless devices has driven the development of novel key generation protocols. Various schemes for extracting symmetric cryptographic keys out of wireless channel properties have been proposed during recent years, making the generation protocol more and more efficient for individual applications. However, often these schemes were evaluated based on theoretical models and without considering practical effects. We present a system for PHY-based key generation with two legitimate users as well as a passive attacker of equivalent power and analyze results from practical measurements in real world scenarios. Furthermore we extend practical constraints by considering heterogeneous setups and show the impact onto representative performance indicators. René Guillaume, Fredrik Winzer, Andreas Czylwik, Christian T. Zenger, Christof Paar |
VTC Fall | 4 |
| 2013 | Efficient E-Cash in Practice: NFC-Based Payments for Public Transportation Systems
Gesine Hinterwälder, Christian T. Zenger, Foteini Baldimtsi, Anna Lysyanskaya, Christof Paar, Wayne P. Burleson |
Privacy Enhancing Technologies | 2 |